Hacker News new | ask | show | jobs
by Grokify 17 days ago
This seems to be primarily an issue with a few specific package management solutions that have suffered SCA vulnerabilities recently, not generaly across the board.
1 comments

It’s foolish to feel safe because your package management solution hasn’t been attacked yet.

The attack vector is generalized.

It’s rational to feel much safer in the Java packages ecosystem, where pinned versions are the default and the norm, and packages cannot run any install-time scripts.